Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jhf3-xxhw-2wpp

Опубликовано: 30 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

go-git: Maliciously crafted idx file can cause asymmetric memory consumption

Impact

A vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a Denial of Service (DoS) condition.

Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files.

Patches

Users should upgrade to v5.17.1, or the latest v6 pseudo-version, in order to mitigate this vulnerability.

Credit

The go-git maintainers thank @kq5y for finding and reporting this issue privately to the go-git project.

Пакеты

Наименование

github.com/go-git/go-git/v5

go
Затронутые версииВерсия исправления

>= 5.0.0, <= 5.17.0

5.17.1

EPSS

Процентиль: 4%
0.00147
Низкий

5 Medium

CVSS3

Дефекты

CWE-191
CWE-770

Связанные уязвимости

CVSS3: 5
ubuntu
4 месяца назад

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.

CVSS3: 5
redhat
4 месяца назад

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.

CVSS3: 5
nvd
4 месяца назад

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.

CVSS3: 5
debian
4 месяца назад

go-git is an extensible git implementation library written in pure Go. ...

CVSS3: 5
redos
22 дня назад

Уязвимость portainer-ce

EPSS

Процентиль: 4%
0.00147
Низкий

5 Medium

CVSS3

Дефекты

CWE-191
CWE-770